Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cherry-pick #14404 to 7.x: Added support for intel.log zeek module #14612

Merged
merged 2 commits into from
Nov 22, 2019

Conversation

andrewkroh
Copy link
Member

Cherry-pick of PR #14404 to 7.x branch. Original message:

Enrich the #14150 supporting intel.log

Co-Authored-By: Arcuri Davide dadokkio@gmail.com

* Added support for intel.log zeek module

Enrich the elastic#14150 supporting intel.log

Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>

* Update fields.yml

Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>

* intel.log

example intel.log

Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>

* added default_field: false

added default_field: false

Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>

* Generate expected zeek/intel output event

* Add changelog entry

* Update field docs

* Misc improvements

Expand dots in zeek.intel.seen
Parse ts value without dropping millisecond value
Add event.ingested timestamp
Convert ingest node pipeline to YAML
Save JSON message in event.original

* Updates to zeek.intel.seen

Expand dots of all seen.* fields
Change name of zeek.intel.seen.fa_file to zeek.intel.seen.f as documented by Zeek.

* Update field docs

(cherry picked from commit 7ad14e6)
@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@andrewkroh andrewkroh merged commit 0902147 into elastic:7.x Nov 22, 2019
@andrewkroh andrewkroh deleted the backport_14404_7.x branch January 14, 2022 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants